Megalodon Campaign Backdoors GitHub Repositories via CI Workflow Compromise (Campaign)
ID: d11ed007-c46b-517b-a562-cf12ced03d81
STIX ID: report--d11ed007-c46b-517b-a562-cf12ced03d81
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-05-22
Date Updated: 2026-05-29
Author: [email protected] (Wiz Threat Research)
Megalodon is a large-scale software supply-chain campaign that compromised thousands (~5,500) GitHub repositories by injecting malicious GitHub Actions workflows which exfiltrated CI/CD secrets, cloud credentials, SSH keys, OIDC tokens, Kubernetes and Terraform credentials, and also poisoned npm package releases; attackers used forged CI identities and likely leveraged compromised personal access tokens or deploy keys, employing both auto-executing workflows and dormant workflow_dispatch backdoors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
